7.5
CVSSv3

CVE-2021-33317

Published: 11/05/2022 Updated: 20/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet to the device, an attacker can crash the process due to null pointer dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trendnet ti-pg1284i_firmware

trendnet ti-g102i_firmware -

trendnet ti-g160i_firmware -

trendnet ti-g642i_firmware -

trendnet ti-pg102i_firmware -

trendnet ti-pg541i_firmware -

trendnet ti-rp262i_firmware -

trendnet teg-30102ws_firmware -

trendnet tpe-30102ws_firmware -